Kevin Risden commented on HBASE-20406:

If I were to guess it would be OPTIONS. TRACE is the one that came up on a 
security scan at work. I just used the existing method since it did the trick.

> HBase Thrift HTTP - Shouldn't handle TRACE/OPTIONS methods
> ----------------------------------------------------------
>                 Key: HBASE-20406
>                 URL: https://issues.apache.org/jira/browse/HBASE-20406
>             Project: HBase
>          Issue Type: Improvement
>          Components: security, Thrift
>            Reporter: Kevin Risden
>            Assignee: Kevin Risden
>            Priority: Major
>         Attachments: HBASE-20406.master.001.patch
> HBASE-10473 introduced a utility HttpServerUtil.constrainHttpMethods to 
> prevent Jetty from answering on TRACE and OPTIONS methods. This should be 
> added to Thrift in HTTP mode as well.

This message was sent by Atlassian JIRA

Reply via email to